# Second Eyes Agent Workflow Services (npm · @secondeyes/mcp-unblock)

Workflow diagnostics, capability routing, and x402 settlement for MCP-compatible agents.

- Trust score: 76/100 (medium)
- Change this week: +32
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `secondeyesai.com`: 56/100, [markdown](https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/api-bar.md), [page](https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/api-bar)
- npm · `@secondeyes/mcp-unblock`: 76/100 (this document), [markdown](https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/secondeyes-mcp-unblock.md), [page](https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/secondeyes-mcp-unblock)

## Channel facts

- Registry: `npm`
- Package: `@secondeyes/mcp-unblock`
- Version: `1.2.7`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (113 of 117), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (113 of 117), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to This-Is-Hellgate/second-eyes-ai).
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 26 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 64/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 1286 tokens (~116/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 89/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 60% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add this-is-hellgate-secondeye-mcp-unblock -- npx -y @secondeyes/mcp-unblock
```

### Codex

```bash
codex mcp add this-is-hellgate-secondeye-mcp-unblock -- npx -y @secondeyes/mcp-unblock
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "this-is-hellgate-secondeye-mcp-unblock": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@secondeyes/mcp-unblock"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add this-is-hellgate-secondeye-mcp-unblock --command npx --arg -y --arg @secondeyes/mcp-unblock
```

### Hermes

```yaml
mcp_servers:
  this-is-hellgate-secondeye-mcp-unblock:
    command: "npx"
    args: ["-y", "@secondeyes/mcp-unblock"]
```

### Other

```json
{
  "mcpServers": {
    "this-is-hellgate-secondeye-mcp-unblock": {
      "command": "npx",
      "args": [
        "-y",
        "@secondeyes/mcp-unblock"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 76, +56)

- [security improvement] Install scripts: unverified → pass
- [security improvement] Provenance: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [security] The attested source repository moved: This-Is-Hellgate/second-eyes-ai
- [functional regression] Security disclosure: fail → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Stability: unverified → 0.23
- [functional improvement] Schema quality: unverified → good
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional] First check of Schema quality: unverified
- [functional] Licence: MIT

### 2026-07-31 (score 20, −24)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-27 (score 44)

First indexed and scored.

## MCP tools (11)

### `proof_bar` (~72 tokens)

Service proof

Free, read-only. Verify the Second Eyes service is live and the x402 Base payment rail is active before spending any USDC. Returns pass:true with per-rail evidence. Run this first — if pass is false, no paid call will succeed. Recommended starting point before enter_lounge or any order_service call.

Output parameters:

- `pass` (boolean)
- `status` (number)

### `patron_activity` (~63 tokens)

Execution activity

Free, read-only. Check whether other agents have successfully purchased from Second Eyes and view their on-chain transaction receipts on Base. Use before spending to confirm the payment rail has real settlement history. Returns agent count, purchase count, and recent Base transaction hashes you can verify independently.

Output parameters:

- `status` (number)

### `read_menu` (~83 tokens)

Capability catalogue

Free, read-only. List all 12 recovery and verification capabilities available for purchase, each priced $0.01–$0.05 USDC on Base. Each item maps a named agent failure state (looping, blocked, overloaded, uncertain, about to pay) to its slug and exact price. Call before order_service to confirm the right slug for your situation.

Output parameters:

- `status` (number)

### `read_laws` (~68 tokens)

Service policies

Free, read-only. Read the deterministic rules that govern every session: idle timeout (120s), free window (15 min), strike policy, session limits, and spend caps. Reference when a session behaves unexpectedly or before building an automated workflow that holds a session open across multiple order_service calls.

Output parameters:

- `status` (number)

### `read_pricing` (~80 tokens)

Pricing

Free, read-only. Get the session time pricing curve (free for the first 15 minutes, then $0.10–$2.00/min compounding) plus the per-capability prices for all slugs. Use to calculate maximum cost exposure before enter_lounge, especially when operating under a strict spend cap or planning a long-running session.

Output parameters:

- `status` (number)

### `enter_lounge` (~83 tokens)

Create workflow session

Free. Open a compatibility session and receive a session_id required by pause_and_route and order_service. Supply a stable agent_id you control. Returns session.id, your patron mark, and session headers. Call after proof_bar confirms the service is live. Sessions expire after 120s of inactivity — keep them short.

Input parameters:

- `agent_id` (string, required): Stable agent identifier

Output parameters:

- `session_header`
- `status` (number)

### `pause_and_route` (~134 tokens)

Pause and route

Free, once per session. Describe a stuck or failed state and receive a routing verdict: which capability slug to call next and why. Input your current task, state description, and failure count. Output is a recommended slug (e.g. mcp-wiring, loop-detect, claim-check) to pass to order_service. Use when you know something is wrong but not which service fixes it. Requires a session_id from enter_lounge.

Input parameters:

- `failure_count` (number)
- `session_id` (string, required): session.id from enter_lounge
- `state` (string)
- `task` (string)

Output parameters:

- `status` (number)

### `order_service` (~419 tokens)

Execute workflow capability (paid)

COSTS USDC (Base) — launch pricing $0.01–$0.05 per call (max $0.05). Order a workflow capability by slug. Compatibility path: proof_bar → enter_lounge (get session_id) → order_service. Paid slugs return HTTP 402; if MCP_X402_WALLET_KEY is set on the MCP server process the payment auto-settles inline via x402 v2 (USDC on Base eip155:8453) and the tool returns the paid result with paid_via_mcp_x402:true. If no wallet is configured the tool returns the 402 body with x402_error.code and REST retry instructions. Autopay-default slugs (zero-arg, convert to a paid 200): loop-detect | scope-check | context-recover | tool-verify | cascade-break | pitstop | pre-run-context | claim-check | context-compress | mcp-wiring | should-i-pay | receipt | help-me | schema-repair. Excluded from zero-arg autopay because they need a caller-supplied input this tool cannot pass: transcribe-extract | doc-extract — call /api/bar/x402/transcribe and /api/bar/x402/extract directly with the required input (a blind order_service retry would reach the door and dead-end on no_input).

Input parameters:

- `session_id` (string, required): session.id from enter_lounge (carried as X-Second-Eye-Session)
- `slug` (string, required): Zero-arg autopay slug, each ≤ $0.05 USDC: loop-detect | scope-check | context-recover | tool-verify | cascade-break | pitstop | pre-run-context | claim-check | context-compress | mcp-wiring | should-…

Output parameters:

- `paid_via_mcp_x402` (boolean): true when the wallet auto-settled the 402
- `payment` (object)
- `payment_required` (boolean)
- `status` (number): 200 when paid/served, 402 when payment could not be completed
- `x402_error` (object)

### `leave_with_receipt` (~86 tokens)

Leave with receipt

Free. Close the current compatibility session and receive an itemized receipt listing all capabilities ordered, total USDC spent, session duration, and grant IDs for each purchase. Call at the end of every workflow. The receipt is the only record of the session — Second Eyes retains no task content after the session closes.

Input parameters:

- `session_id` (string, required): session.id from enter_lounge

Output parameters:

- `status` (number)

### `fetch_catalog` (~68 tokens)

Full catalog

Free, read-only. Retrieve the full capability catalogue including the extended tiers beyond the standard menu: nano taps ($0.05), micro taps ($0.25), and tool packs ($1.00). Use when read_menu is not sufficient and you need all available slugs across every pricing tier.

Output parameters:

- `status` (number)

### `github_mcp_401_fix` (~130 tokens)

github-mcp 401 fix shortcut

Shortcut for a specific failure: github-mcp returning 401 after a PAT is configured. Automatically routes through pause_and_route then orders the mcp-wiring capability ($0.05 USDC), which returns the full PAT scope, stdio path, and SSE wiring guide. Requires a session_id from enter_lounge. Auto-settles payment when MCP_X402_WALLET_KEY is set on the MCP server process; otherwise returns the 402 body with REST payment instructions.

Input parameters:

- `error_detail` (string)
- `session_id` (string, required): session.id from enter_lounge

Output parameters:

- `service_status` (number)
- `status` (number)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/secondeyes-mcp-unblock#diagnostics

## Score history

- 2026-08-03: 76
- 2026-08-02: 76
- 2026-08-01: 20
- 2026-07-31: 20
- 2026-07-30: 44
- 2026-07-28: 44
- 2026-07-27: 44

## Links

- npm package: https://www.npmjs.com/package/@secondeyes/mcp-unblock
- Socket report: https://socket.dev/npm/package/@secondeyes/mcp-unblock
- Repository: https://github.com/This-Is-Hellgate/second-eyes-ai
- Website: https://secondeyesai.com/api/bar
- Changelog RSS feed: https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/secondeyes-mcp-unblock/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/secondeyes-mcp-unblock/changelog.json
- HTML version of this page: https://verifymcp.io/servers/this-is-hellgate-secondeye-mcp-unblock/secondeyes-mcp-unblock
